IP Library Granted Patent US 9,445,245
Granted Patent B2
US 9,445,245 · App. 13/539,675 · Granted Sep 13, 2016

Short message service spam data analysis and detection

Inventors: Ilona Murynets (Rutherford, NJ); Roger Piqueras Jover (New York, NY)
Assignee: AT&T Intellectual Property I, L.P.
H04W4/14H04L51/12H04M3/42382
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,445,245
App. No.
13/539,675
Granted
Sep 13, 2016
Kind
B2
Abstract

A method and apparatus for identifying a potential source of SMS spam are disclosed. For example, the method collects a plurality of call detail records, extracts at least one feature from each of the plurality of call detail records, and identifies the potential source of the short message service spam by analyzing the at least one feature that is extracted from each of the plurality of call detail records.

Claims (40)

1. A method for identifying a potential source of a short message service spam, the method comprising:

collecting, by a processor, a plurality of call detail records associated with a plurality of short message service messages, wherein a device type allocation code is included in each of the plurality of call detail records;

extracting, by the processor, the device type allocation code from each of the plurality of call detail records, wherein the device type allocation code identifies a manufacturer of a device that is originating the plurality of short message service messages and a model type of the device;

comparing, by the processor, the device type allocation code to a device type watch list, wherein the device type watch list includes device type allocation codes of model types that are associated with short message service spam originators;

identifying, by the processor, the device as the potential source of the short message service spam when the device type allocation code is contained in the device type watch list; and

blocking, by the processor, communications from an account, the account using the device that has been identified as the potential source of the short message service spam based upon the device type allocation code being contained in the device type watch list, wherein the blocking of the account is based on an entropy of time between consecutive short message service messages associated with the account.

2. The method of claim 1 , wherein the device type allocation code is extracted from an international mobile equipment identity number of the device that is included in each of the plurality of call detail records.

3. The method of claim 2 , wherein the comparing further comprises comparing the international mobile equipment identity number to a device watch list.

4. The method of claim 1 , wherein the blocking further comprises blocking the account using the device that has been identified as the potential source of the short message service spam based upon an international mobile equipment identity number of the device.

5. The method of claim 1 , further comprising:

extracting a geographic origin from each of the plurality of short message service messages, wherein the blocking is further based on the geographic origin being associated with sources of short message service spam.

6. The method of claim 1 , wherein the device type allocation code comprises one feature of a plurality of features extracted from each of the plurality of call detail records.

7. The method of claim 6 , wherein the plurality of features is used to calculate a response ratio of a number of incoming short message service messages to a number of outgoing short message service messages.

8. The method of claim 6 , wherein the plurality of features is used to calculate a ratio of a volume of short message service messages versus a volume of voice calls.

9. The method of claim 6 , wherein the plurality of features is used to determine a geographic pattern of a plurality of messages that is sent.

10. The method of claim 9 , wherein the geographic pattern comprises a number of geographic destinations of the plurality of messages that is sent, where the number of geographic destinations is determined based upon an area code of each intended recipient of each of the plurality of messages that is sent.

11. The method of claim 1 , wherein the collecting the plurality of call detail records is performed by an application server interacting with a billing server.

12. The method of claim 1 , wherein the identifying uses a decision tree.

13. The method of claim 1 , further comprising:

providing a feedback comprising an identification of the device that has been identified as the potential source of the short message service spam.

14. A non-transitory computer-readable storage medium storing a plurality of instructions which, when executed by a processor, cause the processor to perform operations for identifying a potential source of a short message service spam, the operations comprising:

collecting a plurality of call detail records associated with a plurality of short message service messages, wherein a device type allocation code is included in each of the plurality of call detail records;

extracting the device type allocation code from each of the plurality of call detail records, wherein the device type allocation code identifies a manufacturer of a device that is originating the plurality of short message service messages and a model type of the device;

comparing the device type allocation code to a device type watch list, wherein the device type watch list includes device type allocation codes of model types that are associated with short message service spam originators;

identifying the device as the potential source of the short message service spam when the device type allocation code is contained in the device type watch list; and

blocking communications from an account, the account using the device that has been identified as the potential source of the short message service spam based upon the device type allocation code being contained in the device type watch list, wherein the blocking of the account is based on an entropy of time between consecutive short message service messages associated with the account.

15. The non-transitory computer-readable storage medium of claim 14 , the operations further comprising:

extracting an international mobile equipment identity number of the device from each of the plurality of short message service messages, wherein the blocking is further based on the international mobile equipment identity number.

16. The non-transitory computer-readable storage medium of claim 14 , wherein the device type allocation code is extracted from an international mobile equipment identity number of the device that is included in each of the plurality of call detail records.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the comparing further comprises comparing the international mobile equipment identity number to a device watch list.

18. An apparatus for identifying a potential source of a short message service spam, the apparatus comprising:

a processor; and

a non-transitory computer-readable medium storing instructions which, when executed by the processor, cause the processor to perform operations, the operations comprising:

collecting a plurality of call detail records associated with a plurality of short message service messages, wherein a device type allocation code is included in each of the plurality of call detail records;

extracting the device type allocation code from each of the plurality of call detail records, wherein the device type allocation code identifies a manufacturer of a device that is originating the plurality of short message service messages and a model type of the device;

comparing the device type allocation code to a device type watch list, wherein the device type watch list includes device type allocation codes of model types that are associated with short message service spam originators;

identifying the device as the potential source of the short message service spam when the device type allocation code is contained in the device type watch list; and

blocking communications from an account, the account using the device that has been identified as the potential source of the short message service spam based upon the device type allocation code being contained in the device type watch list, wherein the blocking of the account is based on an entropy of time between consecutive short message service messages associated with the account.

19. The apparatus of claim 18 , wherein the device type allocation code is extracted from an international mobile equipment identity number of the device that is included in each of the plurality of call detail records.

20. The apparatus of claim 19 , wherein the comparing further comprises comparing the international mobile equipment identity number to a device watch list.

Assignments (4)
SECURITY INTEREST Recorded Feb 14, 2023
From: RINGCENTRAL, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062973/0194 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2019
From: AT&T INTELLECTUAL PROPERTY I, L.P.
To: RINGCENTRAL, INC.
Reel/Frame 050824/0312 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SECOND INVENTOR'S LAST NAME PREVIOUSLY RECORDED ON REEL 028579 FRAME 0498. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. INVENTOR NAME SHOULD READ: PIQUERAS JOVER, ROGER. Recorded Oct 7, 2019
From: MURYNETS, ILONA; PIQUERAS JOVER, ROGER
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 051344/0285 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2012
From: MURYNETS, ILONA; JOVER, ROGER PIQUERAS
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 028579/0498 →
Continuity (1)
Related Publication 20140004892A1 · Jan 2, 2014